<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Does btool logs its usage somewhere? in Security</title>
    <link>https://community.splunk.com/t5/Security/Does-btool-logs-its-usage-somewhere/m-p/517089#M11748</link>
    <description>&lt;P&gt;Can you try running btool with —no-log option and check if that’s displaying some output?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 31 Aug 2020 18:44:14 GMT</pubDate>
    <dc:creator>thambisetty</dc:creator>
    <dc:date>2020-08-31T18:44:14Z</dc:date>
    <item>
      <title>Does btool logs its usage somewhere?</title>
      <link>https://community.splunk.com/t5/Security/Does-btool-logs-its-usage-somewhere/m-p/313073#M8191</link>
      <description>&lt;P&gt;All,&lt;/P&gt;

&lt;P&gt;Looking at some windows logs and came across the following commands ran on two separate computers. The "--no-log" concerns me and I can't seem to find if there is a place where logs would generate when this command is ran. &lt;/P&gt;

&lt;P&gt;Has anyone seen or know why I would be seeing this? I am the only admin for these hosts so at first glance this looks like a bad actor.&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/4701i2F8C9EB884FDDAE0/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Apr 2018 13:39:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Does-btool-logs-its-usage-somewhere/m-p/313073#M8191</guid>
      <dc:creator>jordanking1992</dc:creator>
      <dc:date>2018-04-04T13:39:19Z</dc:date>
    </item>
    <item>
      <title>Re: Does btool logs its usage somewhere?</title>
      <link>https://community.splunk.com/t5/Security/Does-btool-logs-its-usage-somewhere/m-p/313074#M8192</link>
      <description>&lt;P&gt;Hi @jordanking1992&lt;/P&gt;

&lt;P&gt;Please check the usage of the btool command.&lt;/P&gt;

&lt;P&gt;splunkhome/bin/splunk btool "conf file prefix" list --debug --app="appname"| grep "if you want to grep something from conf file"&lt;/P&gt;

&lt;P&gt;and also use "&amp;gt; /var/tmp/123.txt" to write results into text file&lt;/P&gt;

&lt;P&gt;here is the link to splunk doc&lt;/P&gt;

&lt;P&gt;&amp;amp; splunk does writes logs about btool in splunkhome/var/log/splunk/bttol.log&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 04 Apr 2018 21:55:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Does-btool-logs-its-usage-somewhere/m-p/313074#M8192</guid>
      <dc:creator>PowerPacked</dc:creator>
      <dc:date>2018-04-04T21:55:06Z</dc:date>
    </item>
    <item>
      <title>Re: Does btool logs its usage somewhere?</title>
      <link>https://community.splunk.com/t5/Security/Does-btool-logs-its-usage-somewhere/m-p/313075#M8193</link>
      <description>&lt;P&gt;Thanks for the information but the question is "What am I seeing in those screenshots?".  I cannot find the --no-log anywhere in the documentation.&lt;/P&gt;

&lt;P&gt;-Jordan&lt;/P&gt;</description>
      <pubDate>Thu, 05 Apr 2018 12:44:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Does-btool-logs-its-usage-somewhere/m-p/313075#M8193</guid>
      <dc:creator>jordanking1992</dc:creator>
      <dc:date>2018-04-05T12:44:02Z</dc:date>
    </item>
    <item>
      <title>Re: Does btool logs its usage somewhere?</title>
      <link>https://community.splunk.com/t5/Security/Does-btool-logs-its-usage-somewhere/m-p/313076#M8194</link>
      <description>&lt;P&gt;Can you post the full windows logs ? so to figure out why do you see these ?&lt;/P&gt;</description>
      <pubDate>Thu, 05 Apr 2018 12:52:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Does-btool-logs-its-usage-somewhere/m-p/313076#M8194</guid>
      <dc:creator>splunker12er</dc:creator>
      <dc:date>2018-04-05T12:52:00Z</dc:date>
    </item>
    <item>
      <title>Re: Does btool logs its usage somewhere?</title>
      <link>https://community.splunk.com/t5/Security/Does-btool-logs-its-usage-somewhere/m-p/517085#M11747</link>
      <description>&lt;P&gt;Hi did you ever determine what the root of this was? I'm seeing the same thing in my environment and would like to understand what's going on.&lt;/P&gt;</description>
      <pubDate>Mon, 31 Aug 2020 18:07:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Does-btool-logs-its-usage-somewhere/m-p/517085#M11747</guid>
      <dc:creator>clozach</dc:creator>
      <dc:date>2020-08-31T18:07:30Z</dc:date>
    </item>
    <item>
      <title>Re: Does btool logs its usage somewhere?</title>
      <link>https://community.splunk.com/t5/Security/Does-btool-logs-its-usage-somewhere/m-p/517089#M11748</link>
      <description>&lt;P&gt;Can you try running btool with —no-log option and check if that’s displaying some output?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 31 Aug 2020 18:44:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Does-btool-logs-its-usage-somewhere/m-p/517089#M11748</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2020-08-31T18:44:14Z</dc:date>
    </item>
  </channel>
</rss>

